logo

Another npm supply chain worm is tearing through dev environments

ID: 71634a4f-951d-559b-8707-4a6c8268fa1c

STIX ID: report--71634a4f-951d-559b-8707-4a6c8268fa1c

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2026-04-22

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

**Executive summary:** A self-propagating CanisterWorm-style supply-chain malware campaign has infected multiple npm packages (including @automagik/genie, pgserve, @fairwords/*, @openwebconcept/*), is actively stealing developer credentials, cloud and CI secrets, browser extension and crypto wallet data, and exfiltrating to a webhook and an ICP canister (canister ID cjn37-uyaaa-aaaac-qgnva-cai); it also contains logic to inject and republish malicious packages (and upload PyPI packages if credentials are found), and shows strong tradecraft overlap with prior TeamPCP-linked infections though attribution is not confirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.